openSUSE-SU-2017:3419-1
Dashboard / Vulnerabilities / openSUSE-SU-2017:3419-1
openSUSE-SU-2017:3419-1
Summary: Security update for enigmail
Details: This update for enigmail to version 1.9.9 fixes the following issues (boo#1073858): * Enigmail could be coerced to use a malicious PGP public key with a corresponding secret key controlled by an attacker * Enigmail could have replayed encrypted content in partially encrypted e-mails, allowing a plaintext leak * Enigmail could be tricked into displaying incorrect signature verification results * Specially crafted content may cause denial of service
References: https://lists.opensuse.org/archives/list/[email protected]/thread/Z4PY6AADWKLV7IK565VIPYQLCGKGZCCK/#Z4PY6AADWKLV7IK565VIPYQLCGKGZCCK, https://bugzilla.suse.com/1073858
Affected packages
Package
Name: enigmail
Purl: pkg:rpm/suse/enigmail&distro=SUSE%20Package%20Hub%2012
Affected ranges
Type: ECOSYSTEM
Events:
